Description
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
Remediation
References
Related Vulnerabilities
PHP Out-of-bounds Read Vulnerability (CVE-2017-12933)
WordPress 4.5.x Multiple Vulnerabilities (4.5 - 4.5.15)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17302)
Unfiltered header injection in Apache 1.3.34/2.0.57/2.2.1
XWiki Improper Preservation of Permissions Vulnerability (CVE-2021-21379)